Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.94% | — | Hms-networks Ewon FlexyAIHms-networks Cosy PlusAI | 13/3/2026 | 17/6/2026 | HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have a stack buffer overflow that leads to a Denial of Service, which can also be exploited to achieve Unauthenticated Remote Code Execution. | |
| Aplazada | Alta (7.5) | 0.63% | — | Hms-networks Ewon FlexyAIHms-networks Cosy PlusAI | 13/3/2026 | 17/6/2026 | HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 allows unauthenticated attackers to cause a Denial of Service by using a specially crafted HTTP request that leads to a reboot of the device, provided they have access to the… | |
| Aplazada | Crítica (9.1) | 0.20% | — | Hms-networks Ewon FlexyAIHms-networks Cosy PlusAI | 13/3/2026 | 17/6/2026 | HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have weak entropy for authentication cookies, allowing an attacker with a stolen session cookie to find the user password by brute-forcing an encryption parameter. | |
| Aplazada | Alta (8.8) | 0.85% | — | Hms-networks Ewon FlexyAIHms-networks Cosy PlusAI | 13/3/2026 | 17/6/2026 | HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have improper neutralization of special elements used in an OS command allowing remote code execution by attackers with low privilege access on the gateway, provided the attacker… | |
| Aplazada | Alta (8.6) | 0.64% | — | Hms-networks Ewon Flexy 205AI | 19/12/2024 | 17/6/2026 | A code injection vulnerability in HMS Networks Ewon Flexy 205 allows executing commands on system level on the device. This issue affects Ewon Flexy 205: through 14.8s0 (#2633). | |
| Modificada | Baja (2.3) | 0.34% | — | Hms-networks Ewon Flexy FirmwareHms-networks Ewon Cosy Firmware | 18/9/2020 | 17/6/2026 | All version of Ewon Flexy and Cosy prior to 14.1 use wildcards such as (*) under which domains can request resources. An attacker with local access and high privileges could inject scripts into the Cross-origin Resource Sharing (CORS) configuration that could abuse this vulnerability, allowing the attacker to retrieve… | |
| Modificada | Media (6.1) | 0.69% | — | Hms-networks Ewon Flexy FirmwareHms-networks Ewon Cosy Firmware | 8/4/2020 | 17/6/2026 | A non-persistent XSS (cross-site scripting) vulnerability exists in eWON Flexy and Cosy (all firmware versions prior to 14.1s0). An attacker could send a specially crafted URL to initiate a password change for the device. The target must introduce the credentials to the gateway before the attack can be successful. |